ROOKDocs
GET

List authorization rules

ENDPOINT/v1/authorization-rules

Returns authorization-control rules for the program, newest first. Filter by state and type. This operation is program-scoped.

Authentication & Headers

HeaderTypeRequirementDescription
AuthorizationstringREQUIREDAPI key passed as an HTTP Bearer token: Bearer rk_live_...
X-Program-IDUUIDPROGRAM-SCOPEDProgram boundary UUID that scopes the issuing card, wallet, or transfer.

Query Parameters

ParameterTypeRequirementDescription
statestringOPTIONAL
Return only rules in this state. Omit to return `ACTIVE` and `INACTIVE`.
Allowed:ACTIVEINACTIVE
typestringOPTIONAL
Return only rules of this type. Omit to return every type.
Allowed:CONDITIONAL_BLOCKVELOCITY_LIMITMERCHANT_LOCKCONDITIONAL_ACTION
pageintegerOPTIONAL
1-based page index. Default 1. Values below 1 are treated as 1.
page_sizeintegerOPTIONAL
Number of objects to return in the page. Minimum 1, maximum 100, default 10. Also accepted as `page-size`. Values below 1 fall back to the default; values above 100 are capped at 100.
order_bystringOPTIONAL
Field to sort by. When omitted, the endpoint uses its default order. Also accepted as `order-by`. Valid fields are endpoint-specific (`created_at`, `updated_at`, …).
ascendingbooleanOPTIONAL
Sort direction. Default true (ascending). Pass `false` for descending. Invalid values are ignored and the default is used.

Response Codes & Schemas

200A page of authorization rules.
application/json
{
  "data": [
    {
      "id": "8e4c1a92-2f70-4c45-9b3d-0a1e6f7c8290",
      "object": "authorization_rule",
      "name": "Block high-risk MCC",
      "state": "ACTIVE",
      "scope": {
        "type": "PROGRAM"
      },
      "type": "CONDITIONAL_BLOCK",
      "current_version": {
        "id": "b7e3d190-4c6a-4e82-9f15-2d8a0c7b3941",
        "object": "authorization_rule_version",
        "version": 1,
        "parameters": {
          "type": "CONDITIONAL_BLOCK",
          "conditions": [
            {
              "attribute": "MCC",
              "operation": "IS_ONE_OF",
              "value": [
                "7995",
                "5813"
              ]
            }
          ]
        },
        "created_at": "2026-08-12T09:00:00Z",
        "updated_at": "2026-08-12T09:00:00Z"
      },
      "draft_version": null,
      "created_at": "2026-08-12T09:00:00Z",
      "updated_at": "2026-08-19T17:45:00Z"
    },
    {
      "id": "5a2c9e18-7d4b-4f01-a8c3-6e9b1d0f4527",
      "object": "authorization_rule",
      "name": "Daily spend cap",
      "state": "ACTIVE",
      "scope": {
        "type": "WALLET",
        "wallet_ids": [
          "4d8f2a10-6c3e-4b91-9e5a-2f7c8d1e0b44"
        ]
      },
      "type": "VELOCITY_LIMIT",
      "current_version": {
        "id": "6b3d0f29-8e5c-4102-b9d4-7f0c2e1a5638",
        "object": "authorization_rule_version",
        "version": 1,
        "parameters": {
          "type": "VELOCITY_LIMIT",
          "velocity": {
            "limit_amount": {
              "amount": 50000,
              "currency": "USD"
            },
            "limit_count": 20,
            "period": {
              "type": "DAY"
            },
            "filters": null
          }
        },
        "created_at": "2026-08-14T10:00:00Z",
        "updated_at": "2026-08-14T10:00:00Z"
      },
      "draft_version": null,
      "created_at": "2026-08-14T10:00:00Z",
      "updated_at": "2026-08-14T10:00:00Z"
    }
  ],
  "total_count": 2
}
400Bad Request: malformed JSON, failed schema validation, or conflicting parameters.
application/json
{
  "error": {
    "type": "invalid_request_error",
    "code": "invalid_request",
    "message": "invalid order by: foo. Valid options are: [created_at updated_at]",
    "param": "order_by",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/invalid_request"
  }
}
401Unauthorized: missing, malformed, or unknown API key.
application/json
{
  "error": {
    "type": "authentication_error",
    "code": "authentication_error",
    "message": "A valid API key is required.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/authentication_error"
  }
}
403Forbidden: the API key is denied by RBAC, or it cannot access this program. A resource that exists on another program or organization returns `404 not_found`, not `403`.
application/json
{
  "error": {
    "type": "permission_error",
    "code": "permission_denied",
    "message": "The API key cannot access this program.",
    "param": "X-Program-ID",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/permission_denied"
  }
}
404Not Found: unknown id, or the resource is not visible to this API key.
application/json
{
  "error": {
    "type": "not_found_error",
    "code": "not_found",
    "message": "No card found for the given id.",
    "param": "card_id",
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/not_found"
  }
}
429Too Many Requests: the API key exceeded its rate limit.
application/json
{
  "error": {
    "type": "rate_limit_error",
    "code": "rate_limited",
    "message": "Rate limit exceeded. Retry after the number of seconds in Retry-After.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/rate_limited"
  }
}
500Internal Server Error: unexpected failure. Retry with the same Idempotency-Key.
application/json
{
  "error": {
    "type": "api_error",
    "code": "internal_error",
    "message": "An unexpected error occurred. Retry with the same Idempotency-Key.",
    "param": null,
    "request_id": "550e8400-e29b-41d4-a716-446655440000",
    "doc_url": "https://docs.rookpayments.com/errors/internal_error"
  }
}